Noweb/Noroff Insecure Temporary File Creation Vulnerability
BID:7937
Info
Noweb/Noroff Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 7937 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0381 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 16 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to Jakob Lell. |
| Vulnerable: |
Norman Ramsey Noweb 2.9 a |
| Not Vulnerable: | |
Discussion
Noweb/Noroff Insecure Temporary File Creation Vulnerability
noweb/noroff has been reported prone to an insecure temporary file creation vulnerability. As a result, it may be possible for local attackers to corrupt files owned by the user who is invoking the noroff application.
An attacker may exploit this vulnerability to corrupt, potentially sensitive arbitrary files.
It should be noted that although this vulnerability has been reported to affect noweb version 2.9a, other versions might also be affected.
noweb/noroff has been reported prone to an insecure temporary file creation vulnerability. As a result, it may be possible for local attackers to corrupt files owned by the user who is invoking the noroff application.
An attacker may exploit this vulnerability to corrupt, potentially sensitive arbitrary files.
It should be noted that although this vulnerability has been reported to affect noweb version 2.9a, other versions might also be affected.
Solution / Fix
Noweb/Noroff Insecure Temporary File Creation Vulnerability
Solution:
Debian has released an advisory (DSA 323-1). Information about applying fixes is available in the referenced advisory. Fixes are available below.
Gentoo Linux has released an advisory. Users who have installed app-text/noweb are advised to upgrade affected systems to noweb-2.9-r3 by issuing the following commands:
emerge sync
emerge noweb
emerge clean
Norman Ramsey Noweb 2.9 a
Solution:
Debian has released an advisory (DSA 323-1). Information about applying fixes is available in the referenced advisory. Fixes are available below.
Gentoo Linux has released an advisory. Users who have installed app-text/noweb are advised to upgrade affected systems to noweb-2.9-r3 by issuing the following commands:
emerge sync
emerge noweb
emerge clean
Norman Ramsey Noweb 2.9 a
-
Debian nowebm_2.9a-5.1potato_alpha.deb
Alpha
http://security.debian.org/pool/updates/main/n/noweb/nowebm_2.9a-5.1_a lpha.deb -
Debian nowebm_2.9a-5.1potato_i386.deb
IA-32
http://security.debian.org/pool/updates/main/n/noweb/nowebm_2.9a-5.1_i 386.deb -
Debian nowebm_2.9a-7.3woody_alpha.deb
Alpha
http://security.debian.org/pool/updates/main/n/noweb/nowebm_2.9a-7.3_a lpha.deb -
Debian nowebm_2.9a-7.3woody_arm.deb
ARM
http://security.debian.org/pool/updates/main/n/noweb/nowebm_2.9a-7.3_a rm.deb -
Debian nowebm_2.9a-7.3woody_hppa.deb
HP
http://security.debian.org/pool/updates/main/n/noweb/nowebm_2.9a-7.3_h ppa.deb -
Debian nowebm_2.9a-7.3woody_i386.deb
IA-32
http://security.debian.org/pool/updates/main/n/noweb/nowebm_2.9a-7.3_i 386.deb -
Debian nowebm_2.9a-7.3woody_m68k.deb
Motorola 680x0
http://security.debian.org/pool/updates/main/n/noweb/nowebm_2.9a-7.3_m 68k.deb -
Debian nowebm_2.9a-7.3woody_mips.deb
Big endian MIPS
http://security.debian.org/pool/updates/main/n/noweb/nowebm_2.9a-7.3_m ips.deb